Every alarm, boarding continue and calendar invitation on your phone depends on a content document that holds all clock regulation a authorities has always announced. A UCLA instructor named Paul Eggert keeps that document current in his spare time, and at smallest four milliard Android phones and iPhones peruse it. He is an open origin maintainer, and he is far from the lone one in that position.
The xkcd humorous that gets posted following all safety scare, figure 2347, shows a tower of contemporary infrastructure stable on one small obstacle that a sole individual maintains without thanks. A Redditor posting as u/Mastbubbles set out to test how near that is to the truth. They downloaded the complete former of 23 projects that phones, browsers and servers depend on, counted everyone who made ten or additional changes in the former year, and published the results on sheets.works as The People Holding Up the Internet. The article collected concerning 1,100 upvotes on r/linux in its archetypal day.
Eleven of the 23 projects had one or two group doing the regular work. The remainder of this part covers who those group are, what prosperity reaches them, and anywhere r/linux pushed rear on the numbers.

Key Findings at a Glance
- 11 of 23 projects had one or two group making ten or additional changes between 7 October 2025 and 7 October 2026.
- xz has a sole regular contributor, Lasse Collin, who wrote 97 percent of its changes in 2025. The inspection established no new backing following the 2024 backdoor.
- sudo had 5,408 of its 5,409 changes from 2008 to 2018 arrive from one person, Todd Miller.
- Eight projects, including the period area database, SQLite, zlib, xz and bash, display no aid or sponsorship in any community backing origin the inspection checked.
- Money follows disasters. Within two months of Heartbleed in 2014 the Linux Foundation had raised $5.4 million, and OpenSSL, which lived on concerning $2,000 a twelvemonth in donations, got paid developers and an audit.
How the Count Works
The author took all project’s complete community history, kept the changes written between 7 October 2025 and 7 October 2026, and remaining out merges and bots. Anyone alongside ten or additional changes in that opening counts as a regular contributor. For funding, “no community grant” method nothing from the Sovereign Tech Agency, Alpha-Omega, Open Collective or GitHub Sponsors. It does not average nobody has always paid these people. The limits division near the end covers what the method misses.
The One-Person Projects: xz, sudo, attack and the Time Zone Database
xz: The Backdoor That Put One Maintainer in the Spotlight
Lasse Collin, who lives in Finland, looks following xz, the compression tool established on nearly all Linux server. In June 2022 he told the mailing catalog that this was an voluntary hobby project and that his capability to keep up had been limited, mostly by long-term mental health issues. For months, accounts calling themselves Jigar Kumar and Dennis Ens had been complaining in community concerning how gradually things moved, during a contributor named Jia Tan sent helpful patches. Collin gave Jia Tan additional access.
By 2023 Jia Tan was making additional changes than Collin, 304 to 172. In February 2024 the versions Jia Tan released carried a hidden way into Linux servers. Andres Freund, an engineer at Microsoft, established it on 29 March since his SSH logins were using additional processor period than they should, before most Linux systems had shipped it. The path into sshd ran through allocation patches: multiple distros nexus OpenSSH to libsystemd, and libsystemd pulls in liblzma, which is part of xz. Nobody has established out who Jia Tan is.
Collin is on his own again. He wrote 97 percent of xz’s changes in 2025, and in 2026 the project has one regular contributor. The inspection established no new prosperity following the backdoor, which is the contrary of what happened to OpenSSL following Heartbleed (more on that below).
The Time Zone Database: One Lecturer, One Backup, Four Billion Devices
Eggert has been the authoritative coordinator of the period area document since 2012 and teaches device discipline at UCLA. Android, iOS and most servers peruse the document to activity out local time. Release 2026e, published on 29 September, opens alongside Manitoba’s move to imperishable -05 on 31 October, which tells phones in Winnipeg not to set their clocks rear on 1 November.
Of the 251 changes made to the document in the former year, Eggert made 218 and Tim Parenti made 28. In 2020 Eggert asked the mailing catalog to create Parenti his backup, in case withdrawal or item alternatively took him away.
The job has carried lawful hazard too. In 2011 an astrology application business sued Eggert and Arthur David Olson, who started the repository in 1986 at the National Institutes of Health, claiming part of its former came from an atlas the business owned. The mailing catalog and download location went offline until IANA took them complete afterward that month. The Electronic Frontier Foundation defended the two men for free, and the business dropped the case in February 2012. Today Eggert has no sponsor page, and the inspection established no community aid for the project.
sudo: The Best-Funded One-Person Project on the List
Todd C. Miller has maintained sudo, the command that gives you admin entitlements on a Mac or a Linux server, since the first 1990s. The tool itself dates to about 1980 at SUNY Buffalo. The inspection established that Miller made 5,408 of the 5,409 changes between 2008 and 2018.
In February 2026 he wrote on his location that he was “in hunt of a sponsor” to keep sudo maintained and developed. After The Register covered the note, the project’s Open Collective prosperity reached concerning $61,700 a twelvemonth and 30 group sponsored it on GitHub. That makes sudo the best-funded one-person project in the count, which says a lot concerning the remainder of the list.
bash: A Bug That Sat Unreported for 25 Years
Chet Ramey has maintained bash, the casing on Linux and, from 2003 to 2019, on Macs, since concerning 1990. He does it alongside his job in the network collection at Case Western Reserve University in Ohio. In September 2014 Stéphane Chazelas reported a flaw that let anyone run commands on a server by sending it specially shaped text. It went community on 24 September as Shellshock and sat on hundreds of millions of machines. The row rearward it had gone into attack on 5 August 1989. The inspection established Ramey’s name on all alter in bash’s community history, including the authoritative fixes.
Smaller Libraries With Huge Reach
- libjpeg-turbo decodes JPEG images on Android phones and in Chrome and Edge. DRC, who signs his emails alongside his initials, wrote 98 percent of this year’s changes and runs the project as a one-person business. At one item he wrote that broad backing covered concerning 8 to 10 hours of activity a month.
- zlib compresses data inner PNG images, Git, Android, iPhones and Chrome. Mark Adler co-wrote it in 1995, and his another job was managing NASA’s Spirit rover on its way to Mars. He and a contributor known as Vollstrecker did most of final year’s work, and Adler has no sponsor page.
- HarfBuzz decides how alphabet associate and sit in Hindi, Arabic, Tamil and most of the world’s scripts, for Android, Chrome, Firefox, Edge and the Kindle. Behdad Esfahbod wrote 85 percent of this year’s changes, alongside five another group doing regular work.
- SQLite is in all Android phone, iPhone and Mac, in Windows 10 and 11, and in all important browser. Four group changed it final year. The project estimates additional than a trillion databases are in use, and the squad pays for the activity by marketing assistance through Hipp’s company.
- core-js lets new JavaScript run in old browsers and, by its author’s count, runs on concerning fractional of the thousand busiest websites. When Denis Pushkarev asked for donations he raised concerning $57 a month. In 2019 he was operating on it complete period without pay whenever a fatal highway accident, which he has described himself, ended in a jail term. He served concerning ten months from January 2020, commits nearly stopped during he was away, and this twelvemonth he wrote 95 percent of the changes.
What Changes When Money Arrives: curl and OpenSSL
Not all project on the catalog runs on one person. Daniel Stenberg started curl in Sweden in 1996, and it now moves data for phones, cars, TVs and Windows, which has shipped it since 2018. Eleven group did regular activity on curl this year, and Stenberg wrote in his assessment of 2025 that everyone alternatively has now added additional lines to it than he has. He plant on it complete period since companies pay for support. The project additionally takes in concerning $89,700 a twelvemonth through Open Collective, Stenberg has 64 sponsors on GitHub, and Germany’s Sovereign Tech Agency paid €195,000 for activity on it.
OpenSSL is the older lesson. In April 2014 the Heartbleed bug let anyone peruse passwords and personal keys out of the recollection of concerning 17 percent of trusted safe servers, by Netcraft’s count. That week the OpenSSL foundation’s president, Steve Marquess, wrote that donations came to concerning $2,000 a year, and he told NPR that one individual worked on the project complete time. Within two months the Linux Foundation had raised $5.4 myriad from innovation companies. OpenSSL got two paid developers and an audit, and its figure of regular contributors went from six in 2013 to fourteen in 2014. In 2026 it has 32.
Set flank by side, the outcomes differ sharply. OpenSSL additional than doubled its regular contributors inside a twelvemonth of Heartbleed. After the xz backdoor the inspection established no comparable money, and xz motionless has one.
Open Source Funding: Who Gets Paid and Who Does Not
The two biggest community funders in the inspection are Germany’s Sovereign Tech Agency, which has funded concerning ninety open origin projects since 2022, and the Alpha-Omega fund, which gave out nearly $6 myriad final year, much of it to safety engineers at foundations specified as Python’s and Ruby’s. Both provision prosperity to organizations that can use for it and study on it. That favors projects alongside an institution rearward them complete one individual alongside a mailing list.
| Project | Funding |
|---|---|
| log4j | €596,160 |
| FFmpeg | €437,930 |
| OpenSSL | €405,888 |
| OpenSSH | €200,000 |
| curl | €195,000 |
No community aid turned up for the period area database, SQLite, zlib, libjpeg-turbo, HarfBuzz, xz, attack or nghttp2. Eggert, Collin, DRC and Adler do not have sponsor pages either.
Money does attain several group by another routes. Nick Wellnhofer raised a low six-figure sum complete the ten years he maintained libxml2, and since August 2026 the City of Munich has paid Sebastian Pipping to activity on expat for up to six months.
Context matters here. “No community grant” is a narrow test, and multiple of these group have day jobs: Eggert teaches at UCLA and Ramey plant in a university network group. What the community document does display is that eight of the 23 projects obtain nothing from those four sources.
libxml2: A Handover That Worked
libxml2 says XML for Android phones, iPhones and Chrome, and the inspection puts it on 5.6 milliard phones and computers. Until December 2025 its README admitted that it was hobbyist application alongside one unpaid maintainer and plentifulness of safety holes. Nick Wellnhofer, who had maintained it for concerning ten years, announced in September 2025 that he was strolling down, kept fixing regressions, and took himself off the maintainers catalog in December. About dozen hours afterward new maintainers were added. Daniel Garcia Moreno has done most of the activity since.
Why You Only Hear Their Names When Something Breaks
Look at which names create headlines: Heartbleed, Shellshock, Jia Tan. The group who established those bugs get a mention, Stéphane Chazelas for Shellshock and Andres Freund for xz. The group who spent years keeping the code operating rarely do.
Some evade notice on purpose. DRC signs his emails alongside his initials, and SQLite’s location formerly took downward its leaf of developer names and photos, saying several group power misuse the information. The 2011 lawsuit shows what can happen whenever a maintainer is noticed: Eggert and Olson were sued complete a document they gave distant for free.
The r/linux thread added a small correction on recognition. A commenter who took Eggert’s functioning systems way stated calling him a instructor undersells him, since what he taught shaped their career.
What r/linux Made of the Numbers
The most average reply was rage at companies that container these libraries to billions of devices and pay lone for what is flashy or crucial to their own operations. One commenter asserted that firms marketing Linux are energetic in the application they depend on, and another replied that the dull projects on this catalog are exactly the ones that get nothing. A long-time commenter traced the issue to language: liberated application talked concerning people, entitlements and responsibilities, during open origin talked concerning process, and the duty part got lost.
The sharpest disagreement was complete distributions. Some commenters stated all grave distro forks and patches its packages, so a solitary upstream maintainer is lone part of the story. Others answered that backports are not the identical as upstream resilience, since distros motionless depend on the first author for releases, scheme and profound cognition of the code.
The xz case divided the thread. One flank stated the backdoor surfaced inside weeks of release, which shows open assessment working. The another flank stated it was spotted since one engineer chased a few hundred milliseconds of additional SSH login time, and that akin attacks may have gone unnoticed. A third comment noted that the attackers succeeded by wearing downward one maintainer, so contributor figure solitary is an incomplete measure of safety.
A skeptic asserted that these maintainers are not overwhelmed and that there is not adequate activity to validate a team. That holds finest for mature, stable tools and worst on the day the one maintainer leaves. One commenter noted that GnuPG is missing from the list, and multiple disliked the scroll animations on the first page. A plain type exists, connected in the sources below.
How Far to Trust the Numbers
The figure is a helpful indication alongside genuine limits.
- A commit’s author is not continually the maintainer, and several projects publish their former as a copy of another system, which can skew who gets credit.
- Commit counts young female reviewing, bug triage, safety reports and publish work, so a quiescent log can conceal a lot of effort.
- Mature application changes slowly. A low commit figure can average finished, not neglected.
- “No community grant” covers four named sources, so personal assistance and director period do not display up.
- Device numbers are lesser bounds. A project counts on a phase lone if the author could see it there, and Macs, iPads, servers, cars and TVs are remaining out. The totals lean on community figures of additional than three milliard energetic Android devices, additional than one milliard iPhones and 1.6 milliard Windows machines a month.
The author asked for corrections in the two the part and the Reddit post, and the libxml2 division was corrected alongside assistance from Nick Wellnhofer in October 2026.
Check What Your Own System Depends On
You can see part of this on your own machine. Run the command below to catalog which of these libraries curl pulls in.
ldd "$(command -v curl)" | grep -E 'libz\.so|libssl|libnghttp2'
On Ubuntu 24.04 it prints zlib (libz.so.1), nghttp2 and OpenSSL (libssl.so.3). That is three of the 23 projects, loaded by one command-line tool. Point the identical command at another programs you use all day and additional names volition rotate up. The first part additionally has a equipment picker for Android, iPhone, Mac, Windows and Linux that shows which of these projects sit inner each.
How to Support Open Source Maintainers
- Sponsor the tools you use daily. sudo and curl the two obtain sponsorships through GitHub and Open Collective, and sudo’s backing grew following a sole news story.
- Put it in a business budget. If your director ships or runs Linux, ask for a recurring fee to the projects your stack depends on. It is small next to the disbursal of an incident.
- Ask your distro what it gives back. One r/linux commenter asserted that distributions are finest placed to prosperity upstream projects since they cognize what they depend on.
- Report bugs alongside a reproducer, and a place if you can. Skip the demands. Public force on a tired maintainer was part of the xz story.
- Offer to assessment and triage. Maintainers need hands for the unglamorous work, and they volition observe out concerning whom they rely for the identical reason.
- If you keep item critical, scheme the handover. Eggert named a backup in 2020, and libxml2 had new maintainers concerning dozen hours following Wellnhofer stepped away.
The Bottom Line
The code on this catalog is not the feeble point. Most of it is old, studied and stable. The feeble item is the institution about it: one person, a day job, a mailing list, and now and afterward a alien offering to help. The xz case showed that this institution is a safety issue as fine as a fairness problem, and the OpenSSL case showed that a small prosperity changes it quickly.
These maintainers wrote item useful, gave it away, and the remainder of the industry built on top. Learn their names now. The substitute is learning them from a CVE.
Sources and Further Reading
- The People Holding Up the Internet, the first interactive inspection on sheets.works
- Plain type of the identical piece, without the scroll animations
- xkcd 2347: Dependency
- IANA Time Zone Database
- XZ Utils backdoor leaf from the xz maintainers
- The Heartbleed bug
- Most extensively deployed SQL repository engine, sqlite.org
- Sovereign Tech Agency